The Temporal authorization guide says a worker-role token can poll task queues; polling needs write #161

Open
opened 2026-10-05 02:09:58 +00:00 by cgalo5758 · 0 comments
Owner

Where

docs/temporal-authorization-setup.md, the section on giving worker permissions to the service account and not to users (around line 126), and the token example after it.

What it says

The service account's token carries default:worker, which lets the console poll task queues, and keeping default:worker off user tokens limits what a leaked user token can do.

What it should say, or what is missing

Under Temporal's default authorizer the worker permission grants nothing. Every call a worker makes (polling a task queue, completing a task, sending a heartbeat) requires write on the namespace. write also allows starting, signalling, terminating and deleting any workflow in the namespace, and it passes every read call, because the authorizer compares roles by size. The sources are common/api/metadata.go and common/authorization/default_authorizer.go in the Temporal server, checked at 1.29.1.

So the guide should say:

  • The console's service account needs default:write. default:worker does nothing unless the deployment runs a custom authorizer.
  • The protection comes from keeping write, not worker, off user tokens.
  • Whether the service account needs default:admin at all. The test seed grants it default:read, default:write, default:admin and default:worker (test/seed/keycloak/seed-keycloak.sh:523), which makes the console's worker token an administrator of the namespace. If the console makes no admin calls, the guide and the seed should drop admin.
### Where `docs/temporal-authorization-setup.md`, the section on giving worker permissions to the service account and not to users (around line 126), and the token example after it. ### What it says The service account's token carries `default:worker`, which lets the console poll task queues, and keeping `default:worker` off user tokens limits what a leaked user token can do. ### What it should say, or what is missing Under Temporal's default authorizer the `worker` permission grants nothing. Every call a worker makes (polling a task queue, completing a task, sending a heartbeat) requires `write` on the namespace. `write` also allows starting, signalling, terminating and deleting any workflow in the namespace, and it passes every read call, because the authorizer compares roles by size. The sources are `common/api/metadata.go` and `common/authorization/default_authorizer.go` in the Temporal server, checked at 1.29.1. So the guide should say: - The console's service account needs `default:write`. `default:worker` does nothing unless the deployment runs a custom authorizer. - The protection comes from keeping `write`, not `worker`, off user tokens. - Whether the service account needs `default:admin` at all. The test seed grants it `default:read`, `default:write`, `default:admin` and `default:worker` (`test/seed/keycloak/seed-keycloak.sh:523`), which makes the console's worker token an administrator of the namespace. If the console makes no admin calls, the guide and the seed should drop `admin`.
cgalo5758 added the
kind
docs
area/opssecurity
labels 2026-10-05 02:09:58 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: wiki-cafe/member-console#161